MIS311 Management Information Systems

Management Information SystemsUnit 1014 min read

INFOSEC: Threats, Controls, Ethics & Compliance

Unit 10 of Management Information Systems explores how hotels and businesses protect digital assets, covering cyber threats (malware, phishing, DDoS), security controls (preventive, detective, corrective), access management, encryption, disaster recovery, and ethical/legal compliance (GDPR, Nepali IT Act). Real-world c

TAKEAWAYS

  • Cyber threats (malware, phishing, DDoS) exploit human error and system vulnerabilities—hotels are prime targets for data breaches (guest records, payment details).
  • Security controls (preventive, detective, corrective) must be layered (e.g., firewalls + antivirus + incident response) to mitigate risks like ransomware attacks on property management systems.
  • Access control (authentication, authorization, accounting) ensures only authorized staff (e.g., front desk vs. kitchen) can modify sensitive data in hotel software like Opera PMS.
  • Encryption (symmetric/asymmetric) protects data in transit (e.g., online bookings on Yatra.com) and at rest (e.g., guest databases in Nabil Bank’s hotel partnerships).
  • Disaster recovery (backups, redundancy) is critical for hotels—imagine Kathmandu’s Hyatt Regency losing reservation data during a power outage.
  • Ethical/legal compliance (GDPR, Nepali IT Act) requires hotels to disclose data collection (e.g., eSewa’s terms for online payments) and handle breaches transparently.

1. Why Information Security Matters in Hospitality

Hotels handle sensitive data:

  • Guest data: Names, passport numbers, credit card details (PCI-DSS compliance).
  • Operational data: Inventory (e.g., Daraz’s supplier systems), staff records, financials.
  • Intellectual property: Loyalty program algorithms (e.g., Marriott Bonvoy).

Real-world example: When Ncell’s mobile payment system (eSewa) was hacked in 2021, attackers stole NPR 10 million by exploiting weak two-factor authentication (2FA). Hotels using eSewa for payments must enforce multi-factor authentication (MFA) and tokenization (replacing card numbers with tokens).


2. Types of Cyber Threats to Hotels

Threats exploit human error, software flaws, or physical access. Classify them using this mermaid flowchart:

mindmap
  root((Cyber Threats in Hospitality))
    Malware
      Ransomware["Locks files (e.g., Opera PMS databases)"]
      Spyware["Steals data (e.g., guest Wi-Fi passwords)"]
      Trojans["Disguised as legitimate software (e.g., fake 'hotel discount' apps)"]
    Phishing
      Email["Fake 'room upgrade' offers with malicious links"]
      Vishing["Voice calls impersonating IT support"]
      Smishing["SMS with 'booking confirmation' links"]
    DDoS
      Website["Crashes reservation portals (e.g., **Yatra.com** during peak season)"]
      Network["Overloads POS systems (e.g., **KFC Nepal** during lunch rush)"]
    Insider Threats
      Malicious["Disgruntled employee deletes guest records"]
      Negligent["Staff shares passwords (e.g., **Kathmandu’s Thamel hotels**)"]
    Physical Threats
      Tailgating["Unauthorized access to server rooms"]
      Dumpster Diving["Stealing printed reports with credit card data"]

Worked Example: Phishing at a Kathmandu Hotel A front desk agent receives an email:

"Dear Manager, Your reservation system license expires tomorrow. Click here to renew."

  • Red flags:
    • Generic greeting ("Dear Manager").
    • Suspicious URL (hotel-renewal-service[.]com vs. official opera[.]com).
    • Urgency tactic.
  • Impact: If clicked, malware could encrypt the Opera PMS database, locking out staff during check-in.

3. Security Controls: The CIA Triad

Hotels must protect Confidentiality, Integrity, and Availability (CIA). Use this table to compare controls:

Control Type Preventive Detective Corrective
Confidentiality Encryption (AES-256 for guest databases) Audit logs (who accessed records?) Revoke access (e.g., fired employee)
Integrity Hashing (SHA-256 for file integrity) Intrusion detection (IDS) Restore from backup (after ransomware)
Availability Redundant servers (e.g., NTC’s backup data centers) UPS systems (power outages) Disaster recovery plan (DRP)

Visual: Layered Security in a Hotel

flowchart TD
    A["Guest"] -->|"Uses"| B["Public Wi-Fi"]
    B -->|"Firewall"| C["Hotel Network"]
    C -->|"IDS/IPS"| D["Server Room"]
    D -->|"Biometric Access"| E["Database Server"]
    E -->|"Encrypted"| F["Guest Records"]
    F -->|"Backup"| G["Cloud Storage"]
    G -->|"Redundant"| H["Offsite Data Center"]

Real-world tie-in: Nabil Bank’s hotel partners use tokenization (replacing card numbers with tokens) to prevent credit card fraud during online check-ins. This is a preventive integrity control.


4. Access Control: Authentication, Authorization, Accounting (AAA)

Hotels use multi-layered access control to restrict data access. Example for Opera PMS:

Role Authentication Authorization Accounting
Front Desk Agent Username + PIN View/modify reservations Logs all check-ins/outs
Executive Chef Biometric fingerprint Access kitchen inventory only Tracks food waste reports
IT Administrator Smart card + MFA Full system access Monitors all login attempts
Guest OTP (One-Time Password) View own booking only Receipts sent via email

Mermaid Diagram: Access Control Flow

sequenceDiagram
    participant Guest
    participant FrontDesk
    participant PMS
    participant Database
    Guest->>FrontDesk: Shows ID card
    FrontDesk->>PMS: Validates via MFA (OTP)
    PMS-->>FrontDesk: Grants access to booking
    FrontDesk->>Database: Updates status
    Database-->>PMS: Logs action (timestamp + user)

Case Study: Daraz’s Access Control

  • Problem: A Daraz warehouse employee in Kathmandu was caught selling hotel supplies (towels, linens) to competitors.
  • Solution: Daraz implemented:
    • Role-Based Access Control (RBAC): Warehouse staff can only scan inventory, not modify supplier lists.
    • Behavioral Analytics: Flags unusual activity (e.g., downloading large files at odd hours).

5. Encryption: Protecting Data in Transit and at Rest

Hotels use encryption to secure:

  1. Data in transit (e.g., credit card details sent to Khalti).
  2. Data at rest (e.g., guest databases in Nabil Bank’s hotel partnerships).

Comparison Table:

Encryption Type Algorithm Use Case Key Size Example in Hospitality
Symmetric AES Encrypting guest databases 256-bit Opera PMS encrypts reservation files
Asymmetric RSA Secure key exchange (e.g., TLS) 2048-bit HTTPS for online bookings (Yatra.com)
Hashing SHA-256 Verify file integrity (e.g., backups) N/A NTC checks software updates

Visual: TLS Handshake (Secure Bookings)

flowchart LR
    A["Guest Browser"] -->|"1. Hello"| B["Hotel Server"]
    B -->|"2. Certificate"| A
    A -->|"3. Key Exchange (RSA)"| B
    B -->|"4. Symmetric Key (AES)"| A
    A -->|"5. Encrypted Booking Data"| B

Worked Example: Ncell’s Encryption Failure In 2020, Ncell’s eSewa app used weak encryption (128-bit AES instead of 256-bit), allowing hackers to decrypt transaction logs. Lesson: Always use AES-256 for financial data.


6. Disaster Recovery and Business Continuity

Hotels must plan for:

  • Cyberattacks (ransomware).
  • Natural disasters (earthquakes, like 2015 in Nepal).
  • Human error (accidental deletion of guest records).

Key Steps:

  1. Backup: Store copies offsite (e.g., Google Cloud for Hyatt Regency Kathmandu).
  2. Redundancy: Use RAID arrays for databases.
  3. Incident Response Plan: Define roles (e.g., IT team vs. PR team for breach disclosure).

Mermaid Diagram: Disaster Recovery Process

flowchart TD
    A["Disaster Occurs"] --> B["Activate DRP"]
    B --> C["Restore from Backup"]
    C --> D["Notify Stakeholders"]
    D --> E["Monitor Systems"]
    E -->|"If recovered"| F["Resume Operations"]
    E -->|"If not"| G["Escalate to BC Plan"]

Case Study: Kathmandu Traffic’s Impact on Hotels During Dashain, Kathmandu’s Thamel hotels face DDoS attacks on their websites due to overloaded servers. Solution:

  • Cloudflare CDN to distribute traffic.
  • Automated failover to backup servers in Pokhara.

Hotels must follow:

  • Nepali IT Act (2006): Mandates data protection and breach reporting.
  • GDPR (if handling EU guest data): Requires explicit consent for data collection.
  • PCI-DSS: For credit card processing (e.g., Khalti integrations).

Comparison Table:

Law/Standard Applies To Key Requirement Hotel Example
Nepali IT Act All Nepali businesses Report breaches to Nepal Police Cyber Bureau Hyatt Regency must notify within 72 hours
GDPR Hotels with EU guests "Right to be forgotten" (delete data on request) Marriott Bonvoy must comply for European guests
PCI-DSS Credit card processing Tokenization of card data Nabil Bank’s hotel POS systems

Visual: Data Protection Flowchart

flowchart LR
    A["Guest Books Room"] --> B["Hotel Collects Data"]
    B --> C["Encrypts Data"]
    C --> D["Stores Securely"]
    D --> E["Gets Consent"]
    E --> F["Allows Right to Access/Delete"]

Real-world Example: NEPSE’s Data Breach In 2022, NEPSE (Nepal Stock Exchange) exposed investor data due to weak access controls. Hotels must avoid this by:

  • Anonymizing guest data (e.g., replacing names with IDs).
  • Auto-deleting old records (e.g., after 7 years for PCI-DSS compliance).

In the Real World

  1. eSewa (Ncell):

    • Idea Used: Multi-Factor Authentication (MFA) and Tokenization.
    • How: When you pay for a hotel booking via eSewa, the system:
      • Sends an OTP (factor 1: something you know).
      • Uses tokenization (factor 2: something you have—your phone) to replace card details with a one-time token.
    • Risk Mitigated: Even if a hacker steals the OTP, they can’t use the actual card number.
  2. Daraz (Alibaba Group):

    • Idea Used: Role-Based Access Control (RBAC) and Intrusion Detection Systems (IDS).
    • How:
      • Warehouse staff in Daraz’s Kathmandu hub can only scan inventory (no access to supplier contracts).
      • IDS flags unusual activity (e.g., a staff member downloading 1000 product images at 3 AM).
    • Real Impact: Prevented insider theft of hotel supplies (towels, linens) sold to competitors.
  3. Nabil Bank’s Hotel Partnerships:

    • Idea Used: End-to-End Encryption (E2EE) and PCI-DSS Compliance.
    • How:
      • When you book a room on Yatra.com and pay via Nabil Bank’s credit card, the transaction uses:
        • TLS 1.3 (asymmetric encryption for key exchange).
        • AES-256 (symmetric encryption for the actual payment data).
      • The bank never stores your full card number—only a token (PCI-DSS requirement).
    • Why It Matters: Hotels like Kathmandu’s Sofitel avoid credit card fraud during online check-ins.

Exam Tip

How This Unit is Tested

  1. Definitions (5 marks):

    • Expect questions like:
      • "Define ‘phishing’ and give a hotel-specific example."
      • "What is ‘tokenization’? How does Nabil Bank use it?"
    • Answer Tip: Use real-world examples (e.g., eSewa hack, Daraz RBAC).
  2. Scenario-Based Questions (10 marks):

    • "A hotel’s Opera PMS is locked by ransomware. Explain the steps to recover using the CIA triad."
    • Structure Your Answer:
      1. Confidentiality: Restore encrypted files from offsite backups.
      2. Integrity: Verify backups using SHA-256 hashing.
      3. Availability: Switch to redundant servers in Pokhara.
  3. Comparison Tables (5 marks):

    • "Compare symmetric and asymmetric encryption with examples from hotel systems."
    • Use the table above but add:
      Symmetric Asymmetric
      Faster Slower
      Used for bulk data (e.g., Opera PMS databases) Used for key exchange (e.g., TLS handshake)
  4. Case Study Analysis (10 marks):

    • "Analyze how Ncell’s eSewa breach could have been prevented using security controls."
    • Answer Framework:
      1. Threat: Phishing + weak 2FA.
      2. Preventive Control: Enforce MFA (OTP + biometrics).
      3. Detective Control: IDS to detect unusual login attempts.
      4. Corrective Control: Incident response team to isolate compromised accounts.
  5. Ethical/Legal Compliance (5 marks):

    • "A Nepali hotel stores EU guest data. What laws apply? How should they handle a breach?"
    • Answer:
      • Laws: GDPR (EU) + Nepali IT Act (local).
      • Steps:
        1. Notify Nepal Police Cyber Bureau within 72 hours.
        2. Inform affected guests (GDPR requirement).
        3. Conduct a forensic audit to prevent recurrence.

Common Mistakes to Avoid

  • Vague answers: Don’t say "use security"—specify firewalls, MFA, or tokenization.
  • Ignoring real-world examples: Always tie answers to Ncell, Daraz, or Nabil Bank.
  • Mixing up controls: Remember:
    • Preventive = Stops attacks (e.g., firewalls).
    • Detective = Detects attacks (e.g., audit logs).
    • Corrective = Fixes after attacks (e.g., restoring backups).

Final Visual: Security Checklist for Hotels

Based on the TU BHM syllabus for Management Information Systems (MIS311), unit 10.

Discussion

Loading…